laravel/framework · critical · EncryptException

Could not encrypt the data.

Error message

Could not encrypt the data.

What it means

Encrypter::encrypt calls openssl_encrypt with the configured key/cipher/iv; if OpenSSL returns false the payload cannot be encrypted and EncryptException('Could not encrypt the data.') is thrown. False here means the underlying library rejected the inputs (bad key/cipher combination after construction, missing tag for AEAD, or an OpenSSL environment issue) even though the constructor's static check passed.

Solutions

  1. Confirm PHP was compiled with the cipher: php -r 'var_dump(in_array(strtolower("aes-256-gcm"), openssl_get_cipher_methods()));'.
  2. If GCM is unavailable, switch config('app.cipher') to aes-256-cbc and regenerate/keep APP_KEY accordingly.
  3. Ensure you are on a PHP version that supports AEAD ($tag population in openssl_encrypt) — PHP 7.1+ with a modern OpenSSL.
  4. If encrypting custom objects, verify the value is serializable before passing it in.

Example fix

// before
// config/app.php: 'cipher' => 'aes-256-gcm',   (OpenSSL on host lacks GCM)

// after
// config/app.php: 'cipher' => 'aes-256-cbc',
// verify support
if (! in_array('aes-256-cbc', openssl_get_cipher_methods())) {
    throw new RuntimeException('Required cipher not available.');
}
Defensive patterns

Strategy: validation

Validate before calling

$cipher = strtolower(config('app.cipher', 'aes-128-cbc'));

if (! in_array($cipher, openssl_get_cipher_methods(), true)) {
    throw new RuntimeException("Cipher {$cipher} is not available in this PHP/OpenSSL build.");
}

Crypt::encrypt($value);

Type guard

function cipherIsAvailable(string $cipher): bool {
    return in_array(strtolower($cipher), openssl_get_cipher_methods(), true);
}

Try / catch

use Illuminate\Contracts\Encryption\EncryptException;

try {
    return Crypt::encrypt($value);
} catch (EncryptException $e) {
    report(new \RuntimeException('Encryption failed: '.$e->getMessage()));
    throw $e;
}

Prevention

When it happens

Trigger: Calling Crypt::encrypt($value) or Encrypter::encrypt() when openssl_encrypt returns false — typically because the AEAD tag was not captured (GCM cipher with a build of PHP/OpenSSL that does not populate $tag), the data serialization produced an unusable string, or the running PHP was compiled without the requested cipher algorithm.

Common situations: Deploying aes-128-gcm / aes-256-gcm on a PHP build whose OpenSSL lacks GCM support; container images that swap the OpenSSL library; encrypting values that contain non-serializable resources; PHP downgrade after a server move.

Related errors


AI-assisted analysis of laravel/framework@e0f6eb3518 (2026-08-11). Data as JSON: /api/errors/6f513e377055710d. Report an issue: GitHub.

Appendix: source

Thrown at src/Illuminate/Encryption/Encrypter.php:114

     * Encrypt the given value.
     *
     * @param  mixed  $value
     * @param  bool  $serialize
     * @return string
     *
     * @throws \Illuminate\Contracts\Encryption\EncryptException
     */
    public function encrypt(#[\SensitiveParameter] $value, $serialize = true)
    {
        $iv = random_bytes(openssl_cipher_iv_length(strtolower($this->cipher)));

        $value = \openssl_encrypt(
            $serialize ? serialize($value) : $value,
            strtolower($this->cipher), $this->key, 0, $iv, $tag
        );

        if ($value === false) {
            throw new EncryptException('Could not encrypt the data.');
        }

        $iv = base64_encode($iv);
        $tag = base64_encode($tag ?? '');

        $mac = self::$supportedCiphers[strtolower($this->cipher)]['aead']
            ? '' // For AEAD-algorithms, the tag / MAC is returned by openssl_encrypt...
            : $this->hash($iv, $value, $this->key);

        $json = json_encode(['iv' => $iv, 'value' => $value, 'mac' => $mac, 'tag' => $tag], JSON_UNESCAPED_SLASHES);

        if (json_last_error() !== JSON_ERROR_NONE) {
            throw new EncryptException('Could not encrypt the data.');
        }

        return base64_encode($json);
    }

View on GitHub (pinned to e0f6eb3518)